rules-to-hook

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is conceptually coherent with its stated purpose of authoring and enforcing context-inject rules for Claude/VS Code Copilot hooks. The multi-phase auto-discovery and enforcement workflow, along with the Learnings system, provides a comprehensive mechanism to derive, validate, and apply rules. However, several risk signals are present: (1) the installer flow and hook modifications introduce supply-chain and trust considerations without explicit integrity checks; (2) the data flows involve reading and potentially injecting rule content into runtime hooks, which could be misuse-prone if misconfigured; (3) reliance on external subagents and extensive cross-tool coordination increases risk of misalignment or leakage of project context. Overall, the footprint is substantial but aligned with the described purpose; risk is elevated toward suspicious due to potential unverified executables, broad code-reading/prompts, and payload generation. Treat as SUSPICIOUS with a leaning toward benign if robust integrity, attestation, and access controls are present.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:19 PM
Package URL
pkg:socket/skills-sh/andurilcode%2Fctx%2Frules-to-hook%2F@36e9bae92467942b7421ef4f17ecb2065001d405